Microsoft considers surprising change to prevent outages | Tech Reader

Date:

Share:



The massive IT outage from last weekend was not a bad look for CrowdStrike — but Microsoft too. To avoid future large-scale issues, Microsoft is evaluating blocking third-party security software from accessing the Windows Kernel, according to a blog post by John Cable, VP of program management for Windows servicing and delivery.

If this change were to be put in place, the restriction would imitate Apple’s 2020 move, which limited third-party software from accessing its core operating system. The change was introduced in macOS Big Sur, ensuring that every system partition (or volume) that contains the core operating system is cryptographic verified, down to every last file. The goal, of course, is preventing changes from third-party entities that could melt down the whole system. Sound familiar?

Of course, it’s a change easier said than done. Microsoft attempted to do exactly this in 2006 with Windows Vista, preventing third parties from having kernel access. However, the plan failed due to resistance from EU regulators and complaints from — you guessed it — cybersecurity vendors.

In the blog post, John Cable states, “Examples of innovation include the recently announced VBS enclaves, which provide an isolated compute environment that does not require kernel mode drivers to be tamper resistant, and the Microsoft Azure Attestation service, which can help determine boot path security posture.” He goes on to state that they will continue to develop these capabilities and enhance the resiliency of the Windows ecosystem.

In theory, by preventing security software from accessing the kernel, Windows would never again experience the worldwide outage it recently experienced, and that caused 8.5 million PCs to crash due to a CrowdStrike bug. The downside, of course, is that preventing kernel access would also mean that the security software would not be able to monitor for any potential threats. After all, moving in this direction doesn’t mean that other types of attacks are impossible.

Let’s be clear: Microsoft did not confirm that this is the path it will take from now on. But this blog post certainly threw the idea in the air, and that’s significant. More than ever before, there may be a stronger incentive to consider locking down Windows now that we’ve seen the wreckage of the situation.








Source link

━ more like this

Android 17 could turn Gemini into your personal app butler

Google just gave us a real glimpse of how Android 17 might change the way you use your phone. New developer tools announced...

Reform Attracts the Strongest Betting Support This Election – London Business News | Londonlovesbusiness.com

Betting markets suggest heightened interest in today’s Gorton & Denton by-election, with Reform UK and the Green Party gaining notable backing, emphasising their...

Rolls-Royce Profit Jumps £1bn as Defence Orders Surge – London Business News | Londonlovesbusiness.com

Rolls-Royce Holdings has reported a £1 billion surge in annual profit, highlighting its resilience and potential for continued growth, which should reassure investors...

Nearly 400,000 SMEs Fear Closure Ahead of Spring Statement – London Business News | Londonlovesbusiness.com

Almost 400,000 small and medium-sized enterprises (SMEs) are warning they could be forced to close as rising operating costs continue to squeeze margins,...

Perplexity Computer lets you pick the best AI for every task

Perplexity just launched a feature that lets different AI models collaborate on the same task. Called Perplexity Computer, it taps Gemini, Grok, and...
spot_img